Why would stupid employees follow a plan? They are going to click on attachments. They are going to visit malicious sites. And that's assuming they are not disgruntled. If they are disgruntled, they will install malware on purpose.
Most if not all of those issues can solved with a proper security policy...
I’ve worked in some major corporations that did not allow access to the Internet except to approved sites and also would not allow attachments to be opened, software to be installed or removable hard drives to be plugged in....it can be done, but the average organization doesn’t have the expertise or nerve to force these things onto people..